Maryland Longitudinal Data System Center - External Data Sharing With Third-Party Data Centers for Multistate Reporting - Authorization
HB0293 authorizes the Maryland Longitudinal Data System Center to share individual-level student and workforce data with a third-party data center, but only for multistate research and reporting on student outcomes. The bill defines a third-party data center as a secure computational research platform managed outside state government and limits the Center to working with only one such platform at a time. It also repeals a prior provision that allowed the Governing Board to authorize data sharing with the U.S. Census Bureau under certain circumstances.
The bill adds a new statutory section establishing detailed conditions for any external data-sharing arrangement. Before data may be shared, the Governing Board must ensure the third-party platform meets strict security and privacy standards, including FedRAMP authorization, use of de-identified data for analytics, privacy-enhancing techniques such as hashing, and release of only aggregate results. The Center must enter into a written agreement with the platform, the Governing Board must approve the specific data elements, datasets, and projects involved, and the Center must report the arrangement to legislative committees within 30 days and annually thereafter. The Governing Board must also review each agreement every year to confirm continued compliance.
In state law, the bill amends the Education Article provisions governing the Maryland Longitudinal Data System Center and its Governing Board. It adds an explicit authorization for third-party data center sharing, replaces the prior Census Bureau sharing authority, and requires the Governing Board to approve and oversee such sharing under the new section. The practical effect is to create a controlled legal pathway for Maryland education and workforce data to be used in multistate research while preserving existing privacy and security obligations under FERPA and related laws.
The overall sentiment reflected by the bill’s enactment is supportive and cautious: the measure was approved by the Governor and became Chapter 100, suggesting legislative and executive agreement on the value of expanded research capacity. The structure of the bill indicates a strong emphasis on privacy protection, oversight, and transparency, which likely helped address concerns about external data use. No committee transcripts or recorded votes were provided, so there is no direct evidence of opposition in the available materials.
The main points of potential contention are data privacy, the use of personally identifiable information, and the transfer of sensitive student and workforce records to an outside platform. The bill responds to those concerns by limiting the purpose of sharing, requiring FedRAMP-certified security, mandating de-identification and aggregate reporting, and requiring annual review and legislative reporting. Stakeholders most likely to focus on these issues include privacy advocates, education data administrators, researchers, and policymakers concerned with cross-state data matching and accountability.
HB0293 amends the Education Article to expand the Maryland Longitudinal Data System Center’s authority to share student and workforce data externally, but only under a tightly regulated framework for third-party data centers. It creates new statutory requirements for written agreements, security standards, annual review, legislative reporting, and Governing Board approval of each dataset and project. It also repeals the prior authorization related to the U.S. Census Bureau, shifting the statute toward multistate research and reporting arrangements with secure outside platforms.
The available record suggests a generally favorable and cautious sentiment. The bill was enacted into law, indicating support from the General Assembly and the Governor. The text shows a strong policy preference for enabling research and reporting while imposing extensive privacy and security safeguards, which suggests the bill was designed to balance data-sharing benefits with concerns about misuse or identification of individuals.
The most notable contention centers on whether sensitive student and workforce data should be shared outside state government and, if so, under what safeguards. Likely concerns include privacy, re-identification risk, and the adequacy of third-party security controls. The bill addresses those concerns by requiring FedRAMP certification, de-identification, aggregate-only outputs, annual compliance reviews, and formal legislative reporting. No specific opposing arguments or named dissenting stakeholders are provided in the supplied transcripts or vote history.